Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <Xls8qrS5_QdyztMHIXiGOs26w4bnyy7HCqgLUBG9FIGCNqQyMeybftwXamy4KzE_p9kQzxbAtQ7A5PAmRZKAY9S90mHAK5YC9vjHQcxqqgY=@protonmail.com>
Date: Sat, 08 Jul 2023 21:08:38 +0000
From: Barnabás Pőcze <pobrn@...tonmail.com>
To: Tavis Ormandy <taviso@...il.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: manjaro pamac vulnerability

Hi


2023. július 7., péntek 06:44 keltezéssel, Tavis Ormandy <taviso@...il.com> írta:

> FYI, I noticed a blog post about this:
>
> https://github.com/c-skills/vala-vala-hey/blob/master/vala-vala-hey
>
> I didn't test it, but if you can't trust stealth who can you trust? :)
>
> I'm not familiar with manjaro, I dunno if it's the polkit config for their dbus service.
> [...]

It looks like it has been fixed: https://gitlab.manjaro.org/applications/libpamac/-/commit/889aa1d74ad305bb28178396dcc16e5b5381ade6


Regards,
Barnabás Pőcze

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.